NEWS ANALYSIS • 5 mins
Supreme Court Hears Constitutional Challenge to DPDP Act 2023: What Fintech CFOs Must Know
Petitioners have challenged the constitutionality of the DPDP Act 2023 and Rules 2025, citing executive dominance over the Data Protection Board and broad state exemptions. Discover how this impacts fintech compliance budgets, Rule 23(2) gag orders, and vendor consolidation strategies.
Last updated:
What happened
According to the Supreme Court Observer, petitioners have challenged the constitutionality of several sections of the Digital Personal Data Protection Act, 2023 and its associated rules. The core arguments target the structural independence of the Data Protection Board of India and excessively broad government exemptions. Petitioners argue that Section 18 of the Act and Rules 17(1) and 17(2) of the DPDP Rules, 2025 violate the separation of powers due to executive dominance in the DPBI selection committee. Furthermore, Section 36 and Rule 23(2) are being contested for allowing the Union government to demand information from fiduciaries while forcing those fiduciaries to conceal this sharing from the affected users.
Does the DPDP Act apply here
Under Section 3, the Act applies to the processing of digital personal data within the territory of India, and processing outside India if connected to offering goods or services to Data Principals in India. For a fintech enterprise managing high velocity payments and lending pipelines, this constitutional challenge does not pause your baseline compliance obligations. Under Section 4, a person may process digital personal data only for a lawful purpose. Consent is the primary basis for processing, except where Section 7 legitimate uses apply. Until the Supreme Court rules otherwise, CFOs must continue provisioning budgets to meet these statutory mandates.
Legal implications under DPDP
The ongoing litigation highlights significant friction points for data fiduciaries managing state data demands. Petitioners are challenging Section 17(1)(c) and Section 17(2), which exempt the state from standard Act provisions when processing data for offence prevention or national security. Section 36 is specifically contested for allowing the government to compel fiduciaries to furnish information without clear statutory guidance. Crucially for fintech operations, Rule 23(2) of the DPDP Rules, 2025 mandates that fiduciaries must not disclose to Data Principals that their information was furnished to the state under these security exemptions, effectively functioning as a gag order.
Could this happen to you
If your fintech enterprise receives a Section 36 demand tomorrow, your engineering team must isolate and transfer that data without triggering automated user notifications. For a CFO, the risk here is structural and financial. Relying on manual database queries to fulfill government requests while actively suppressing user transparency alerts burns expensive sprint cycles and drives up audit fees. Failing to suppress the notification violates the Rule 23(2) gag order, risking regulatory intervention, while failing to securely log the transfer creates a contingent liability during your next compliance audit. Your Total Cost of Ownership skyrockets if your enterprise relies on fragmented point solutions rather than consolidating vendors who can automate covert government reporting workflows natively.
What companies should do in the next 30 days
1. Model your contingent liability by calculating the EBITDA impact of maximum DPBI penalties, which can reach 250 crore rupees for severe data management failures.
2. Audit your current RBI and DPDP data sharing workflows to ensure your platform can process Section 36 state requests silently, strictly satisfying the Rule 23(2) gag order.
3. Consolidate your compliance SaaS vendors by evaluating platforms that map RBI digital lending guidelines and DPDP requirements in a single dashboard to reduce TCO.
4. Brief your executive board on the constitutional challenge, making it clear that compliance budgeting and vendor selection must proceed despite the ongoing litigation.
What to watch
The Supreme Court proceedings will eventually clarify the operational independence of the DPBI and the exact scope of state data access under Section 17. However, fintech CFOs cannot wait for judicial finality to allocate compliance budgets or upgrade legacy infrastructure. Exactly 274 days remain until the DPDP hard compliance deadline of 13 May 2027. Enterprises must lock in their vendor consolidation strategies now before peak market demand drives up implementation costs. Evaluate your current compliance stack and assess your regulatory exposure today with a baseline assessment at freescan.complydp.com.
Sources
Frequently asked questions
Does the constitutional challenge delay the DPDP Act implementation?
No, the statutory implementation timeline remains active. CFOs must continue budgeting and provisioning for the 2027 compliance deadline to avoid severe contingent liabilities and audit failures.
How does Rule 23(2) impact our data principal rights workflows?
Rule 23(2) of the DPDP Rules 2025 restricts fiduciaries from disclosing to Data Principals that their data was shared with the government for security reasons. Your compliance systems must be capable of handling state data requests silently to obey this gag order.
What are the financial risks if we ignore Section 36 compliance?
Section 36 allows the government to demand information from fiduciaries. Failing to respond accurately, or mismanaging the required data suppression, exposes the enterprise to DPBI penalties and significantly increased audit fees.
Can we use consent as the only basis for sharing data with the state?
Consent is the primary basis for processing, except where Section 7 legitimate uses apply. Under Sections 17 and 36, the state can compel data sharing without user consent for specific security and investigative purposes.
How can a fintech CFO reduce the TCO of DPDP compliance?
Vendor consolidation is the most effective strategy. By unifying RBI digital lending data rules and DPDP consent tracking into one platform, enterprises lower their software costs and reduce the required internal engineering hours.
ComplyDP